Executive brief
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component allows for local privilege escalation. The nft_verdict_init() function incorrectly handles positive values as drop errors, leading to a double free in nf_hook_slow() when NF_DROP resembles NF_ACCEPT.
Affected products
- Linux Linux Kernel versions prior to commit f342de4e2f33e0e39165d8639387aa6c19dff660
Timeline
- 2024-05-30: disclosed
- 2024-05-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-03-27: patched: Commit f342de4e2f33e0e39165d8639387aa6c19dff660
- 2024-04-14: exploited: Public exploit availability noted in references